CVE-2001-0927
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/11/2001
Last modified:
03/04/2025
Description
Format string vulnerability in the permitted function of GNOME libgtop_daemon in libgtop 1.0.12 and earlier allows remote attackers to execute arbitrary code via an argument that contains format specifiers that are passed into the (1) syslog_message and (2) syslog_io_message functions.
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:gnome:libgtop_daemon:1.0.6:*:*:*:*:*:*:* | ||
cpe:2.3:a:gnome:libgtop_daemon:1.0.7:*:*:*:*:*:*:* | ||
cpe:2.3:a:gnome:libgtop_daemon:1.0.9:*:*:*:*:*:*:* | ||
cpe:2.3:a:gnome:libgtop_daemon:1.0.12:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- ftp://ftp.gnome.org/pub/GNOME/stable/sources/libgtop/libgtop-1.0.13.tar.gz
- http://marc.info/?l=bugtraq&m=100689302316077&w=2
- http://www.debian.org/security/2002/dsa-098
- ftp://ftp.gnome.org/pub/GNOME/stable/sources/libgtop/libgtop-1.0.13.tar.gz
- http://marc.info/?l=bugtraq&m=100689302316077&w=2
- http://www.debian.org/security/2002/dsa-098